From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7D08F58F07E for ; Fri, 11 Sep 2026 20:04:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789157046; cv=none; b=YPSTDF8Fq8ZpzqGU2DAvs8y+2XXyEHrzxwNzaRBK1JaCUKTnwQP87GzuEdMSPvHHY7mEkWh510m1Upgt2qCeHnm4UgIKJur1WmBVS+jsCHtepU5QegnExWyFb9gETFFKmkYljurv1GC7o/A4xC7w2+/llt9ES+SdyMirf+sH9NI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789157046; c=relaxed/simple; bh=xC+IPUAql03CswEAM56in9i0UkkPsOyXgilz6GZyjnw=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=d8qLSa17KGuoSzDD8VDI56dlu9ghmS3qD7i91qPY1Gwpr/ICJ9CfRFVTq62nqHiIXJgaCIcyVJb8PVxX/ysyePbMLOInjIDbjaTq0jnutozdrwB4upB8QYKATX9Jwn8i/k012ZAXw16TbSsot8gZU5z1WdkFvt/DqVttOjButDw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=CsNUW8lI; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="CsNUW8lI" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 2A1C71F00899; Fri, 11 Sep 2026 20:03:58 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789157039; bh=auRDH8LSkMbP2qgvXVQxby42XB/v6beFh2rHfj7v2Q8=; h=From:To:Cc:Subject:Date:Reply-To; b=CsNUW8lIO07YsJCF6iI95U9j6KIDcfp0XqnmJJoqp+9cJebOjvFt6zKSwKmcyaTqV cfWuxvh7s00fakoiaedG/iM+GcNDpABEbtbZxBuGGlAS5/SiR/Sj1Ldh0Wx4PQenCL sV2+JduLWcs4ZTW8dqOuh/G56EgpkcSjHBfe0Zo8= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89717: zram: set default primary compressor in zram_destroy_comps() Date: Fri, 11 Sep 2026 21:46:46 +0200 Message-ID: <2026091159-CVE-2026-89717-389b@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=2746; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=ZpJZqdqb6vP1SMOIvUtAGnNO7Mna+FERK/tRSQg1IGY=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLItvvKkzaEGs6Y95n/3rxHdPt7DZyT7kRcUP0yKfXs z3Mqi57dMSyMAgyMciKKbJ82cZzdH/FIUUvQ9vTMHNYmUCGMHBxCsBEfMQY5gdefCxT1VY6QWin kNuP/BOfc+SMVzIsWHLsy8O/qcXci/9cdjwRqDDBKWuaIwA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: zram: set default primary compressor in zram_destroy_comps() Patch series "zram: fix zram issues reported by sashiko". Sashiko drove by and reported [1] a couple of zram issues: a possible BUG_ON() in zlib code due to missing winbits range validation and one possible NULL-ptr dereference in zcomp. Both are low risk yet still worth fixing. This patch (of 2): zram_destroy_comps() resets all compressors and leaves them set to NULL, including the primary one, which is invalid device state, as now comp_algorithm_show()->strcmp() can be called on a NULL compressor. Set default primary compressor in zram_destroy_comps(). The Linux kernel CVE team has assigned CVE-2026-89717 to this issue. Affected and fixed versions =========================== Issue introduced in 6.12 with commit 486fd58af7ac1098b68370b1d4d9f94a2a1c7124 and fixed in 6.18.51 with commit 5cec3e60e9f2d1324179df3aa91656f90095cf8f Issue introduced in 6.12 with commit 486fd58af7ac1098b68370b1d4d9f94a2a1c7124 and fixed in 7.2.4 with commit dea8f13c3dfad8b990f8ea96c997aabeebbc1d22 Issue introduced in 6.12 with commit 486fd58af7ac1098b68370b1d4d9f94a2a1c7124 and fixed in 7.3-rc1 with commit dde75313eed0b014c437f48dd75c0308b592cbf9 Issue introduced in 6.6.57 with commit 6e20720b12299595154857fa98222729f0d5823c Issue introduced in 6.11.4 with commit c4e5683c3031a33dc46954e99d37cbd2f706cdb6 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89717 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/block/zram/zram_drv.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/5cec3e60e9f2d1324179df3aa91656f90095cf8f https://git.kernel.org/stable/c/dea8f13c3dfad8b990f8ea96c997aabeebbc1d22 https://git.kernel.org/stable/c/dde75313eed0b014c437f48dd75c0308b592cbf9